Close Menu
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
Facebook X (Twitter) Instagram
Trending
  • Jennifer Lopez and Ben Affleck reveal summer plans after Europe trip
  • T20 World Cup: Quiet contributions from Akshar Patel, Kuldeep Yadav and Ravindra Jadeja justify Rohit Sharma’s spin vision | Cricket News
  • The impact of a sedentary lifestyle on health
  • Bartok: The World of Lilette
  • Economists say the sharp rise in the U.S. budget deficit will put a strain on Americans’ incomes
  • Our Times: Williams memorial unveiled on July 4th | Lifestyle
  • Heatwaves in Europe are becoming more dangerous: what it means for travelers
  • Christian Science speaker to visit Chatauqua Institute Sunday | News, Sports, Jobs
Facebook X (Twitter) Instagram
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
The Daily PostingThe Daily Posting
Android

Vultur Android malware becomes even more malicious with remote access

thedailyposting.comBy thedailyposting.comApril 2, 2024No Comments

[ad_1]

Virus Android 16x9

According to a recent post from SecurityWeek, Android banking malware, also known as Vultur, has re-emerged with a major update that provides extensive functionality to interact with infected devices and manipulate files. Vultur first surfaced in March 2021, when the malware infects legitimate applications such as AlphaVNC and ngrok to remotely access VNC servers on victims’ devices, allowing them to be accessed through screen recorders and keyloggers. Enabled credential theft.

Upgraded Android Trojan Vultur now has full control over infected devices and access to their files

The latest version of Vultur goes even further, giving you complete control over compromised machines. This includes interfering with applications, posting custom notifications, bypassing lock screen protection, and manipulating files by downloading, uploading, installing, searching, or deleting them.


According to the NCC Group report, the malware primarily relies on AlphaVNC and ngrok for remote access, but the latest version includes enhanced anti-analysis and detection evasion mechanisms. These include multiple payloads, benign app modifications, native code for payload decryption, and AES encryption for command and control (C&C) communications.




The SMS message typically pings the victim and requests them to call a specific number immediately to address the fraudulent transaction. Shortly after, another SMS arrives on the device containing a malicious URL pointing to a modified McAfee Security package that acts as a dropper for the malware itself.

Under a dropper framework called Brunhilda, Vultur consists of three components called payloads, which are intended to facilitate subsequent execution stages. With these payloads in place, Vultur can obtain accessibility service privileges, set up AlphaVNC and ngrok, and perform core backdoor functionality.

Remote control also allows attackers to perform gestures to lock you out of your device

To support remote operations, Vultur includes seven new C&C methods that allow attackers to perform various actions such as click, scroll, and swipe gestures. When we talk about Firebase Cloud Messaging (FCM), there are also 41 new commands that take advantage of these permissions, allowing SMS communications the opportunity to not require persistent connections between sources.

The latest version of Vultur also removes the ability for users to interact with certain applications. This means that the updated Vultur poses a significant risk to Android users as it includes the ability to remotely control infected devices and manipulate files. Therefore, NCC advises Android owners to be careful.

Copyright ©2024 Android Headlines. All rights reserved.

This post may contain affiliate links. Please see our Privacy Policy for more information.

April 2, 2024

[ad_2]

Source link

thedailyposting.com
  • Website

Related Posts

Qualcomm wants to make it easier for phone makers to issue Android updates

June 28, 2024

Qualcomm wants to make Android updates easier for OEMs

June 28, 2024

What’s new in the June 2024 Google system update for Android

June 28, 2024
Leave A Reply Cancel Reply

ads
© 2025 thedailyposting. Designed by thedailyposting.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms of Service
  • Advertise with Us
  • 1711155001.38
  • xtw183871351
  • 1711198661.96
  • xtw18387e4df
  • 1711246166.83
  • xtw1838741a9
  • 1711297158.04
  • xtw183870dc6
  • 1711365188.39
  • xtw183879911
  • 1711458621.62
  • xtw183874e29
  • 1711522190.64
  • xtw18387be76
  • 1711635077.58
  • xtw183874e27
  • 1711714028.74
  • xtw1838754ad
  • 1711793634.63
  • xtw183873b1e
  • 1711873287.71
  • xtw18387a946
  • 1711952126.28
  • xtw183873d99
  • 1712132776.67
  • xtw183875fe9
  • 1712201530.51
  • xtw1838743c5
  • 1712261945.28
  • xtw1838783be
  • 1712334324.07
  • xtw183873bb0
  • 1712401644.34
  • xtw183875eec
  • 1712468158.74
  • xtw18387760f
  • 1712534919.1
  • xtw183876b5c
  • 1712590059.33
  • xtw18387aa85
  • 1712647858.45
  • xtw18387da62
  • 1712898798.94
  • xtw1838737c0
  • 1712953686.67
  • xtw1838795b7
  • 1713008581.31
  • xtw18387ae6a
  • 1713063246.27
  • xtw183879b3c
  • 1713116334.31
  • xtw183872b3a
  • 1713169981.74
  • xtw18387bf0d
  • 1713224008.61
  • xtw183873807
  • 1713277771.7
  • xtw183872845
  • 1713329335.4
  • xtw183874890
  • 1716105960.56
  • xtw183870dd9
  • 1716140543.34
  • xtw18387691b

Type above and press Enter to search. Press Esc to cancel.